CRITICALFortiBleed is actively compromising Fortinet firewalls. Is your domain exposed?
Run free scan
CyberXtron
World Leaks Ransomware Expands Its Victim List with Tata and Reliance-Linked NPCIL in India
#CyberXtron#WorldLeaks#NPCIL#India

World Leaks Ransomware Expands Its Victim List with Tata and Reliance-Linked NPCIL in India

 

Executive Summary

World Leaks, launched on January 1, 2025, is a data-extortion group and rebrand of the former Hunters International RaaS operation, which shut down in November 2024. It follows an exfiltration-first model, stealing and leaking sensitive data instead of encrypting systems. The group has claimed over 170 victims across 29 countries and recently increased targeting of Indian entities, including a disclosure linked to the Kudankulam Nuclear Power Project through a contractor server hosted by Yotta.

Threat Profile

Group Overview

World Leaks is a data-extortion-focused threat group that operates using:

  • Data exfiltration as the primary attack objective
  • Direct extortion against victims via negotiation portal and live chat
  • Public disclosure through a TOR-based leak site
  • A journalist "Insider" early-access program to intensify reputational pressure

The group is a direct rebrand of Hunters International. Hunters International's operators announced the closure of that project on November 17, 2024, citing that ransomware had become too risky and unprofitable due to law enforcement pressure and geopolitical conditions. On January 1, 2025, the same operators relaunched under the World Leaks name with an explicit "no encryption" positioning. Researchers assess this as a rebrand with high confidence, based on reuse of the predecessor's exfiltration tooling, a near-identical affiliate panel and leak-site layout, and continuity of operators and negotiation methodology. The group has publicly denied collaboration with other threat actors and has issued impersonation warnings directing victims to verify contact only through its own listed onion addresses.

Operational Characteristics

World Leaks runs an Extortion-as-a-Service (EaaS) affiliate model built around a proprietary data-exfiltration tool rather than an encryption payload, marking a deliberate departure from its predecessor's ransomware structure.

 

 

Victimology

Overview

Metric 

Value 

Total Victims 

173 

Countries Affected 

29 

Active Since 

January 2025 

Leak Site 

Active 

World Leaks has sustained a steady operational cadence since relaunch, briefly interrupted by an early-2025 infrastructure stability issue that delayed its first published victim to late April 2025. Since then, listing activity has been consistent, with a marked increase in high-profile disclosures through mid-2026.

The victim set spans small and mid-sized firms as well as large multinational institutions, including automotive and electronics manufacturers, financial-services subsidiaries, healthcare networks, public-sector bodies, and critical-infrastructure-adjacent contractors. This variation suggests targeting driven by accessible entry points and data value rather than a fixed size or sector preference.

Geographical Distribution

World Leaks exhibits a broad but unevenly weighted victim footprint, with strong dominance in the United States alongside an expanding international presence.

 

World Leaks exhibits a broad but unevenly weighted victim footprint, with strong dominance in the United States alongside an expanding international presence. The United States represents the primary concentration of victims (91 victims), significantly outweighing all other regions. The next most affected countries are the United Kingdom (10), Brazil (8), Germany (8), Canada (7), and India (7), followed by Japan (5) and Taiwan (4)Additional, lower-volume activity spans Italy, Spain, France, Switzerland, Belgium, Indonesia, Mexico, Pakistan, Sweden, Thailand, Sri Lanka, Hungary, China, Denmark, Finland, Singapore, Serbia, Australia, Colombia, Cameroon, and Romania. This distribution indicates that while the group is not geographically restricted, a discernible regional cluster has formed around Indian manufacturing, energy, and critical-infrastructure-adjacent contractors in recent months, rather than isolated opportunistic hits.

Sector Targeting

 

World Leaks' sector distribution reflects broad, opportunistic targeting rather than a single-industry focus, with the heaviest concentration in healthcare, followed by manufacturing and industrial production, business and professional services, technology and electronics, and consumer services. Financial services, construction, and education follow at roughly comparable levels, with energy, transportation/logistics, hospitality, and agriculture/food production forming a smaller but recurring tier. Retail, consumer goods, and public-sector or critical-infrastructure-adjacent contractors round out a broader but less frequent target set. This spread indicates that targeting is shaped primarily by exposed entry points and data value rather than a narrow vertical preference.

Technical Analysis

Initial Access and Foothold:

Recent victim disclosures and publicly reported incidents indicate that World Leaks primarily gains initial access through compromised credentials targeting internet-facing VPNs, remote-access services, and externally exposed applications. Opportunistic exploitation of vulnerable public-facing systems and phishing campaigns remain secondary access vectors. The group's operations continue to demonstrate a preference for exploiting weak identity security and externally accessible infrastructure over the use of zero-day exploits. 

The increasing concentration of victims across Indian manufacturing, financial services, and critical-infrastructure supply chains suggests deliberate targeting of organizations with high-value intellectual property, engineering documentation, supplier information, and operational records that can maximize extortion leverage after compromise. 

Privilege Escalation, Defense Evasion, and Persistence:

Persistence is commonly achieved through scheduled tasks, Registry Run key modifications, and abuse of legitimate administrative utilities following successful compromise.

Defense evasion techniques include credential theft, selective log manipulation, masquerading of malicious processes as legitimate system activity, and the abuse of trusted Windows components to reduce detection. The group relies heavily on PowerShell and Windows command-line interpreters to perform post-compromise operations while minimizing reliance on custom malware. 

Lateral Movement and Exfiltration:

Lateral Movement

World Leaks primarily performs lateral movement using valid domain accounts together with SMB and Windows administrative shares, supplemented by limited Remote Desktop Protocol (RDP) usage. Current reporting does not indicate consistent deployment of sophisticated lateral movement frameworks, with operators instead favoring legitimate administrative access and native Windows functionality. 

Attack Sequence

  • Initial compromise through exposed VPNs, remote-access infrastructure, compromised credentials, or vulnerable internet-facing applications. 
  • Execution using PowerShell and Windows command-line utilities. 
  • Internal reconnaissance, credential harvesting, and privilege expansion. 
  • Discovery and collection of engineering documents, financial records, intellectual property, supplier data, and business-critical information. 
  • Staging of collected data within the victim environment. 

Automated exfiltration to attacker-controlled infrastructure through the proprietary World Leaks exfiltration platform. 

Extortion through the TOR-based negotiation portal, leak site, searchable file explorer, and Insider journalist early-access program. 

Data Exfiltration

Data exfiltration represents the group's primary operational objective. Affiliates are provided with a proprietary exfiltration client that automates file discovery, indexing, and transfer through SOCKSv5 proxies over the TOR network. Stolen datasets typically remain on affiliate-controlled infrastructure until negotiations conclude, after which selected files or complete datasets may be published through the World Leaks leak portal. Recent disclosures involving Tata Electronics (~630 GB), Reliance Infrastructure (~1.2 TB), and other Indian organizations demonstrate the group's capability to exfiltrate large volumes of sensitive enterprise data. 

Encryption

World Leaks publicly markets itself as an extortion-only operation that does not routinely deploy ransomware encryption. Most documented incidents involve data theft without encrypted-file artifacts. However, inherited capabilities from the Hunters International codebase indicate that encryption functionality remains available, and at least one confirmed 2026 incident involved ransomware deployment. Consequently, organizations should not assume encryption capability is absent during future intrusions. 

Command and Control (C2):

Available intelligence indicates that World Leaks operates a centralized TOR-based infrastructure consisting of a leak site, negotiation portal, affiliate management panel, and Insider journalist portal. Command-and-control and exfiltration communications are conducted through attacker-controlled infrastructure utilizing TOR and multi-hop proxy mechanisms. Public reporting provides limited protocol-level details beyond the use of anonymized communication channels and dedicated onion services for victim negotiations and affiliate operations.

Communication and Platform Analysis

World Leaks operates a four-part infrastructure: a TOR-hosted leak site with a searchable file explorer, a victim negotiation portal with live chat and Bitcoin-only payment tracking, an affiliate management panel, and an "Insider" journalist portal granting media outlets roughly 24-hour advance access to newly disclosed data ahead of public release.

The group has publicly addressed impersonation attempts, stating that its only legitimate contact points are its own listed onion addresses, and has denied formal partnerships with other groups — a claim in tension with observed shared leak-site infrastructure with at least one other extortion operation.

Negotiation Behavior 
World Leaks follows a structured, manually operated negotiation process conducted through its dedicated portal and live chat rather than email-only channels. Victims are provided access to file-browsing views of sampled stolen data to validate claims and maintain pressure. The group applies staged escalation, including partial disclosure ahead of full publication, and has built a distinct pressure mechanism — its journalist early-access program — that is not commonly seen among comparable extortion groups.

Leak Site and Infrastructure Analysis

 

 

World Leaks operates a TOR-based leak ecosystem centered on a single primary leak site paired with a separate negotiation portal and journalist portal, rather than distributed file servers. The leak site presents a searchable company directory with revenue, employee count, and stock-ticker metadata alongside view counters intended to amplify visibility-driven pressure.

The platform includes a file-explorer interface allowing browsing of individual files within a disclosed dataset rather than requiring bulk archive download, and recent updates have added HTTP Range header support for resumable downloads and compression support for bandwidth efficiency.

The ecosystem includes:

  • Leak Site (TOR): Displays victim listings, disclosure status, and file-browsable datasets

  • Negotiation Portal (TOR): Live chat, payment tracking, and sample file access

  • Insider Journalist Portal (TOR): Grants media early access to disclosures ahead of public release

  • Affiliate Panel: Target registration and distribution of the exfiltration tool to partners

Key observations include:

  • Distinct onion addresses for each of the four platform components
  • A searchable, filterable file index observed on at least one disclosed dataset exceeding 1.2 TB across 858,000+ files
  • Public "All" vs. "Published" disclosure-state separation for listed victims
  • A recurring practice of removing victim entries shortly after sample publication, typically indicating active negotiation or payment

Overall, World Leaks' infrastructure reflects a centralized, reputation-amplifying exposure model, where the journalist early-access mechanism and negotiation-portal design distinguish it from groups relying on distributed file servers and manual messaging alone.

NPCIL / Kudankulam Nuclear Power Project Exposure

In mid-July 2026, World Leaks disclosed a large dataset attributed to Reliance Infrastructure, the EPC contractor responsible for common-services Balance of Plant (BoP) work on Units 3 and 4 of the Kudankulam Nuclear Power Project (KKNPP) in Tamil Nadu, India.

 

The exposed data originated from a server belonging to Reliance Infrastructure but hosted by Yotta Data Services Pvt. Ltd., a third-party Indian data-centre provider, within an isolated private-cloud environment dedicated to that customer. Yotta stated its security monitoring detected suspicious activity on the affected server on May 29, 2026, and that the suspicious process was terminated immediately, preventing ransomware execution on that host. Yotta further stated there is no evidence of impact to any other customer environment or to its shared cloud platforms, and that no lateral movement beyond the single server was observed on its side. Reliance Infrastructure was informed of claims of a data breach by the threat actor at the end of June 2026, roughly a month after Yotta's internal detection, and has directed Yotta to conduct a full investigation.

Independent review of the group's leak-site file explorer identified approximately 19,000 files (roughly 14.3 GB) specifically matching KKNPP-related search terms, out of a much larger disclosed Reliance dataset totaling approximately 1.2 TB across 858,000+ files. The material does not appear to relate to the reactors' core nuclear systems, which are supplied by a separate foreign technical partner. It reportedly includes engineering drawings for ventilation, cooling, and common-services buildings; vendor and sub-vendor approval lists; multi-year monthly progress reports; correspondence on extension-of-time requests and change proposals; an insurance policy reportedly valued in the hundreds of millions of dollars covering acts of terrorism against the reactor units; and HR, finance, and administrative records.

The plant operator has characterized the exposed material as pertaining only to conventional common-service facilities typical of any thermal power plant, unrelated to nuclear safety or security systems. Based on available reporting, this is a data exfiltration and threatened-publication event rather than a confirmed encryption event: Yotta's own account frames the activity as a suspected ransomware execution attempt that was interrupted before completing, while the material that ultimately surfaced publicly reflects the exfiltration component of the intrusion. Even absent core reactor system exposure, drawings, vendor lists, and facility layouts of this kind can in principle help map a plant's support infrastructure and identify weaknesses in its security chain.

Recent Indian Targeting Trend  

World Leaks' actively targeting Indian entities has escalated sharply in mid-2026, forming a discernible regional cluster rather than isolated opportunistic hits.

 

Entity 

 

Sector 

 

Notes 

Tata Electronics 

Electronics manufacturing (Apple/Tesla supplier) 

~630 GB / 204,000+ files; reportedly included supplier-mapping documents, quality inspection standards, and third-party OEM drawings marked trade-secret 

Reliance Infrastructure (KKNPP, via Yotta-hosted server) 

Critical infrastructure / nuclear EPC contractor 

~1.2 TB / 858,000+ files disclosed; ~19,000 files tagged to Kudankulam specifically 

RattanIndia Power 

Power generation 

Listed on leak site 

Apollo Pipes 

Industrial manufacturing 

Listed on leak site 

M1xchange 

Financial services 

Listed on leak site 

This is also the second Tata Group subsidiary affected by this actor lineage within roughly eighteen months, a separate Tata entity having been affected under the group's prior identity — raising a recurring supply-chain question for multinational OEMs sourcing from Indian tier-one and tier-two suppliers, and for critical-infrastructure projects relying on third-party-hosted contractor infrastructure.

RANSOM NOTE

 

MITRE ATT&CK TTPs 

Tactic 

Technique ID 

Technique Name 

Reconnaissance 

T1598 

Phishing for Information 

Initial Access 

T1078.002 

Valid Accounts: Domain Accounts 

Initial Access 

T1133 

External Remote Services 

Initial Access 

T1190 

Exploit Public-Facing Application 

Initial Access 

T1566 

Phishing 

Execution 

T1059.001 

Command and Scripting Interpreter: PowerShell 

Execution 

T1059.003 

Command and Scripting Interpreter: Windows Command Shell 

Execution 

T1053.005 

Scheduled Task/Job: Scheduled Task 

Persistence 

T1547.001 

Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder 

Persistence 

T1078.002 

Valid Accounts: Domain Accounts 

Stealth 

T1027.013 

Obfuscated Files or Information: Encrypted/Encoded File 

Stealth 

T1036.005 

Masquerading: Match Legitimate Resource Name or Location 

Stealth 

T1070 

Indicator Removal 

Defense Impairment 

T1685 

Disable or Modify Tools 

Credential Access 

T1003 

OS Credential Dumping 

Credential Access 

T1552.001 

Unsecured Credentials: Credentials In Files 

Credential Access 

T1555 

Credentials from Password Stores 

Discovery 

T1083 

File and Directory Discovery 

Discovery 

T1135 

Network Share Discovery 

Lateral Movement 

T1021.002 

Remote Services: SMB/Windows Admin Shares 

Collection 

T1005 

Data from Local System 

Collection 

T1039 

Data from Network Shared Drive 

Collection 

T1074.001 

Data Staged: Local Data Staging 

Collection 

T1213 

Data from Information Repositories 

Command and Control 

T1071.001 

Application Layer Protocol: Web Protocols 

Command and Control 

T1090.003 

Proxy: Multi-hop Proxy 

Exfiltration 

T1020 

Automated Exfiltration 

Exfiltration 

T1041 

Exfiltration Over C2 Channel 

Exfiltration 

T1048 

Exfiltration Over Alternative Protocol 

Exfiltration 

T1537 

Transfer Data to Cloud Account 

Exfiltration 

T1567.002 

Exfiltration Over Web Service: Exfiltration to Cloud Storage 

Indicators of Compromise (IOCs)

Type 

IOC Value 

IP 

193.149.180[.]50 

IP 

193.161.193[.]99 

IP 

51.15.109[.]222 

Domain 

Smtlawyers[.]ca 

URL 

Hxxps[://]www[.]realtaxcanada[.]com/en/home-en/ 

SHA-256 

7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a 

SHA-256 

94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73 

SHA-256 

c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44 

SHA-256 

e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d 

SHA-256 

e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96 

SHA-256 

eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577 

Leak Site (TOR) 

hxxps://worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion 

Negotiation Portal (TOR) 

hxxps://vw6vklsuotptwdbiwqfvd7y4b57wdbfm6ypxduzzgbt62snti6jm76yd[.]onion 

Insider Journalist Portal (TOR) 

hxxps://3jguvp6xhyypdjgxhxweu4zklse66v3awjj2zljpftcjyeoimepnwtyd[.]onion 

Secondary Contact Domain 

hxxps://shmlxznhxt4wogoo7m5iidw365ocbauwbnmb6rxcxtvlqumlinxqvhqd[.]onion 

 

Mitigations & Recommendations

Initial Access Hardening

  • Enforce multi-factor authentication (MFA) across all external access points
  • Continuously discover and monitor exposed assets, shadow IT, and external attack surface risks using CyberXTron ShadowSpot

Identity & Credential Protection

  • Rotate credentials and OTP seeds for any device suspected of prior compromise, even after patching
  • Implement strict least-privilege access controls across all system

Network Security & Lateral Movement Control

  • Segment networks to isolate critical systems, engineering data, and sensitive vendor environments
  • Monitor internal access behavior for signs of unauthorized lateral movement or privilege misuse

Endpoint Protection & Threat Monitoring

  • Deploy EDR/XDR solutions focused on behavioral detection rather than signature-based alerts
  • Monitor command execution, scripting activity, and abnormal system behavior

Data Protection & Exfiltration Prevention

  • Monitor outbound traffic for large or unusual data transfers, especially to TOR-related or unknown cloud infrastructure
  • Implement Data Loss Prevention (DLP) controls tuned for volume and destination, not just content
  • Classify and minimize sensitive engineering, supplier, and PII datasets; enforce retention limits

External Exposure & Leak Monitoring

  • Continuously monitor dark web and leak sites for early signs of data exposure using CyberXTron DarkFlash 
  • Track unauthorized publication of organizational data and misuse of brand identity
  • Identify unknown internet-facing assets, third-party exposures, and misconfigured services using CyberXTron ShadowSpot

Third-Party & Hosting/Supply Chain Risk

  • Require third-party data-centre and hosting providers to provide documented incident-detection SLAs and mandatory customer notification timelines
  • Audit EPC-contractor and vendor data-handling practices for critical-infrastructure projects
  • Assess downstream exposure whenever a hosting provider or contractor discloses suspicious activity, even if initially described as contained

Incident Response & Extortion Readiness

  • Maintain separate playbooks for data-exposure-only incidents versus ransomware-encryption incidents, given this actor's demonstrated capability for both
  • Retain security logs 90+ days to counter log-suppression techniques
  • Capture forensic disk images before remediation on suspected rootkit-affected devices

Conclusion

World Leaks represents the current identity of a lineage running through Hunters International, reflecting a deliberate strategic pivot toward a data-centric extortion model where the primary objective is extraction and controlled exposure of sensitive information rather than system disruption through encryption. Its operational structure — a centralized TOR-based leak ecosystem, a dedicated negotiation portal, and a journalist early-access program — demonstrates a more coordinated approach to maximizing pressure through visibility and staged disclosure than is typical among comparable extortion groups. The group's escalating focus on Indian manufacturing, electronics, and critical-infrastructure-adjacent contractors, culminating in the Kudankulam-linked disclosure, highlights both operational reach and a forming regional targeting pattern. At a strategic level, World Leaks reflects an evolving threat landscape where data itself is the primary monetized asset, while its inherited encryption capability means organizations should not treat the "extortion-only" positioning as a fixed operational limit. This trend underscores the growing importance of data protection, exposure monitoring, third-party risk management, and identity security as organizations face increasing risk from adversaries prioritizing data exploitation over traditional ransomware deployment.

 

 

Elevate your security—get curated threat insights in your inbox.

World Leaks Ransomware Expands Its Victim List with Tata and Reliance-Linked NPCIL in India | CyberXTron Blog